—
GO-2022-1043
Hardcoded hashed password in github.com/flyteorg/flyteadmin
Quick fix
GO-2022-1043 — github.com/flyteorg/flyteadmin: upgrade to the fixed version with the command below.
go get github.com/flyteorg/flyteadmin@v1.1.44Details
Default authorization server's configuration settings contain a known hardcoded hashed password.
Users who enable auth but do not override this setting may unknowingly allow public traffic in by way of this default password with attackers effectively impersonating propeller.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/flyteorg/flyteadmin
Introduced in:
1.0.0Fixed in: 1.1.44Fix
go get github.com/flyteorg/flyteadmin@v1.1.44